X-Frame-Options: deny Content-Security-Policy: frame-ancestors 'none'
Even if the potential attack does not entail significant risk, it’s a good security practice to add the headers. It is also detected by security scanners, so reports from penetration testers might mention the lack of these headers.